Tombigbee Healthcare Authority, doing business as Whitfield Regional Hospital in Demopolis, Alabama, has notified patients that a cybersecurity incident may have exposed their personal and health information. Healthcare providers hold some of the most sensitive personal information that exists, and are legally and ethically obligated to protect it from unauthorized access.
Whitfield Regional Hospital’s Data Breach Investigation
According to a notification letter filed with the Massachusetts Attorney General’s Office, Whitfield Regional Hospital detected unauthorized access to its network on or about June 8, 2025. Following the discovery, the hospital secured its network, reported the incident to law enforcement, and began working with outside cybersecurity professionals to investigate the scope of the intrusion. The investigation determined that files may have been accessed or removed by an unauthorized party between May 15, 2025 and June 8, 2025. A subsequent review of the potentially impacted data, completed on June 26, 2026, determined that some patients’ personal and/or health information may have been contained in the affected files.
The notification letter does not specify the exact categories of personal or health information involved beyond stating generally that patients personal and health information may have been affected, a common pattern in healthcare breach notices where forensic review to determine the precise data elements per patient can extend well beyond the initial detection date. The roughly one-year gap between detection in June 2025 and the completion of the data review in June 2026 illustrates how long a thorough healthcare data breach investigation can take, particularly when a hospital must cross-reference which specific patient records were contained in the compromised files before it can notify each individual accurately.
Healthcare organizations are among the most frequently targeted entities in data breaches because medical records typically combine multiple high-value data types in one place — names, dates of birth, Social Security numbers, insurance information, and clinical details — creating opportunities for both traditional identity theft and medical identity theft, where a criminal uses a victim’s information to obtain medical services or prescriptions billed to the victim’s insurance. Medical identity theft can be particularly difficult to detect and unwind, since it can corrupt a victim’s own medical records with another person’s treatment history.
Because the specific data types affected in this incident were not detailed in the public version of the notification letter, affected patients should assume the exposure could include any combination of identifying and health-related information typically held by a hospital, and take the credit monitoring and account-vigilance steps described below seriously even without a fully itemized list of what was taken.
When Did This Breach Occur?
Whitfield Regional Hospital detected unauthorized access to its network on or about June 8, 2025. The hospital’s investigation determined that files may have been accessed between May 15, 2025 and June 8, 2025. A review of the affected data was completed on June 26, 2026, at which point notification letters were sent to affected patients.
What Information Was Breached?
The notification letter states that some patients’ personal and/or health information may have been contained in the files affected by this incident. The specific categories of data involved are not itemized in the publicly filed version of the notice.
What You Can Do
Whitfield Regional Hospital is offering complimentary access to Experian IdentityWorks for 12 months, which includes credit monitoring and identity restoration support. Affected patients should enroll before the deadline listed in their letter, consider placing a fraud alert or security freeze with the three major credit bureaus, and review both financial statements and insurance explanation-of-benefits notices for any unfamiliar activity.
File a Data Breach Lawsuit Against Whitfield Regional Hospital
If you received a notification letter from Whitfield Regional Hospital, or believe your personal or health information may have been compromised in this incident, you may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.